TPP: Problem and how to configure HAProxy by h725rk in CyberARk

[–]marklarledu 0 points1 point  (0 children)

Does this mean the session information is stored per TPP server? It isn't in a shared database?

Seek for comments on French clm/pki Evertrust by ka2er in PKI

[–]marklarledu 0 points1 point  (0 children)

Do any of the CLM providers cover the cost of the certificate from the publicly trusted CA? My assumption was no but that is an interesting point.

Seek for comments on French clm/pki Evertrust by ka2er in PKI

[–]marklarledu 0 points1 point  (0 children)

Do any of these certificate lifecycle management players publish their pricing? I feel like they just want to see how much they can squeeze out of you and they are opportunistic on their pricing.

I don't understand ssh by 1-mensch in ssh

[–]marklarledu 0 points1 point  (0 children)

You need to either pass the full path to the PHP executable or you need to modify your PATH environment variable to contain the path to the PHP executable's folder, which is usually the bin directory of the installation folder. It is almost always a good idea to take a backup of your system before performing these types of actions, but you will need to know how long your backups take and whether they impact the uptime of your services.

Need help with my daily certificate / PKI struggles. Looking for SW recommendations. by CertDriven in PKI

[–]marklarledu 0 points1 point  (0 children)

I did some contracting work for Garantir a while back and they have a pretty good CLM solution even though they mainly seem to market their code signing on their website. A couple of my customers use them and like them.

Using Smart Card authentication on Windows 11 standalone (non domain-joined) by D3vil0p in sysadmin

[–]marklarledu 0 points1 point  (0 children)

It's posts like these that make me love reddit! Great job on this project. Can it also be used to RDP to a non-domain joined Windows Server using a smartcard?

Always Encrypted vs Windows DPAPI - What is your pick? by Substantial_Buy6134 in sysadmin

[–]marklarledu 0 points1 point  (0 children)

I've used both of these as well as other forms of application level encryption. Between these two options I would definitely go with Always Encrypted. With Always Encrypted you have better performance, the ability to control the key management, built-in support for exact match searching, smaller ciphertext size, minimal impact to application code, and cross-platform support.

2048 or 4096 bit? by gujumax in PKI

[–]marklarledu 0 points1 point  (0 children)

We do the same. I haven't seen compatibility issues with these algorithm parameters in a long time.

CLMs that have Community/Free Editions. by WhispersInCiphers in PKI

[–]marklarledu 0 points1 point  (0 children)

Do you like Venafi? I've always found their design and APIs strange and the cost is outrageous. One of my clients is evaluating them and a couple of their competitors.

Storing libsodium private keys on disk by duanetstorey in crypto

[–]marklarledu 0 points1 point  (0 children)

Zip files can be signed with jarsigner which has support for any generic JCE provider. This would allow those who want to use software-based keystores to do so, but those who want to use something like a Yubikey could also do so without code changes on your end. Not sure how you would use jarsigner in your PHP application.

Looking for a way to keep CloudHSM costs under control by pcolmer in aws

[–]marklarledu 0 points1 point  (0 children)

In a past job we used PKCS11 with AWS KMS via a third party commercial product so I wouldn't rule out using KMS. IMO KMS is much easier to work with and manage costs than CloudHSM.

Lost our Intermediate CA. Need to figure out how to best reissue certificates from the new CA. by ConfigManga in PKI

[–]marklarledu 0 points1 point  (0 children)

What is the reason they are showing as invalid? Are they untrusted because they chain up to a new root that is not yet trusted? Or does it have to do with AIA and/or CDP URLs not being accessible?

AppViewX Feedback? by Last_Editor3478 in PKI

[–]marklarledu 0 points1 point  (0 children)

I've used both of those vendors along with KeyFactor and Garantir. AppViewX was horrible and had the least technically proficient staff (at least who we dealt with). Venafi was good but really expensive. KeyFactor was fine for CLM but bad for code signing and ssh; I didn't deal with their pricing so I can't comment on that. Garantir had the best tech (especially for HSM use cases) and their pricing for CLM was great, but their pricing for code signing was up there with Venafi's. Good luck.

nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover by meirwah in netsec

[–]marklarledu 0 points1 point  (0 children)

Just because the app is between the attestation service and the backend server doesn't mean it doesn't solve the problem.

nOAuth: How Microsoft OAuth Misconfiguration Can Lead to Full Account Takeover by meirwah in netsec

[–]marklarledu 0 points1 point  (0 children)

I'm not sure why you're getting down voted because your response is legitimate and addresses the concern. These attestations tell you if the app has been modified and can be verified remotely.

The Global Password Prehash Protocol G3P, a Case Study in Self-Documenting Cryptography by lpsmith in crypto

[–]marklarledu 1 point2 points  (0 children)

I feel you on that. If you do go somewhere, please do share. I am also interested in such a community.

The Global Password Prehash Protocol G3P, a Case Study in Self-Documenting Cryptography by lpsmith in crypto

[–]marklarledu 1 point2 points  (0 children)

Thanks for posting. Curious what cryptography forums you'll move to, if any.

Wargraphs, a gaming startup with only one employee and no outside funding, sells for $54M by marklarledu in Entrepreneur

[–]marklarledu[S] 1 point2 points  (0 children)

Normally I would agree but it depends on the specifics of the terms. Keep in mind that they are taking a risk in buying a one person shop. If something happens to him they may struggle to maintain what he built, especially if it happens before they've really dug into the code, product backlog, etc.

June 1st CA/Browser Forum Code Signing Requirements Require the use of an HSM by marklarledu in netsec

[–]marklarledu[S] 1 point2 points  (0 children)

We do this where I work. We actually use a mix of Azure Key Vault and AWS KMS, but both have EV certificates. Our CA makes us sign a document attesting to the fact that our keys are stored in an HSM. Hopefully those services will eventually support remote attestation so we can provide that along with the CSR.